open-menu
closeme
A Member Was Added to a Security-Enabled Global Group
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
A Member Was Removed From a Security-Enabled Global Group
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
A New Trust Was Created To A Domain
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
A Security-Enabled Global Group Was Deleted
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Abused Debug Privilege by Arbitrary Parent Processes
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Account Created And Deleted Within A Close Time Frame
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.defense-evasion
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Account Disabled or Blocked for Sign in Attempts
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Add Port Monitor Persistence in Registry
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.010
·
Share on:
twitter
facebook
linkedin
copy
Added Credentials to Existing Application
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.t1098.001
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Addition of SID History to Active Directory Object
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1134.005
·
Share on:
twitter
facebook
linkedin
copy
Admin User Remote Logon
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.lateral-movement
attack.initial-access
attack.t1078.001
attack.t1078.002
attack.t1078.003
car.2016-04-005
·
Share on:
twitter
facebook
linkedin
copy
Allow Service Access Using Security Descriptor Tampering Via Sc.EXE
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Always Install Elevated MSI Spawned Cmd And Powershell
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Always Install Elevated Windows Installer
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Anomalous User Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.t1098
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Antivirus PrinterNightmare CVE-2021-34527 Exploit Detection
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Application AppID Uri Configuration Changes
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.persistence
attack.credential-access
attack.privilege-escalation
attack.t1552
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Application URI Configuration Changes
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.t1528
attack.t1078.004
attack.persistence
attack.credential-access
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
APT27 - Emissary Panda Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
attack.g0027
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Aruba Network Service Potential DLL Sideloading
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.persistence
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Atbroker Registry Change
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1218
attack.persistence
attack.t1547
·
Share on:
twitter
facebook
linkedin
copy
Attempts of Kerberos Coercion Via DNS SPN Spoofing
calendar
Oct 23, 2025
·
attack.collection
attack.credential-access
attack.persistence
attack.privilege-escalation
attack.t1557.001
attack.t1187
·
Share on:
twitter
facebook
linkedin
copy
Authentications To Important Apps Using Single Factor Authentication
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
AWS IAM Backdoor Users Keys
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
AWS IAM S3Browser LoginProfile Creation
calendar
Oct 23, 2025
·
attack.execution
attack.persistence
attack.defense-evasion
attack.initial-access
attack.privilege-escalation
attack.t1059.009
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
AWS IAM S3Browser Templated S3 Bucket Policy Creation
calendar
Oct 23, 2025
·
attack.execution
attack.t1059.009
attack.persistence
attack.defense-evasion
attack.initial-access
attack.privilege-escalation
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
AWS IAM S3Browser User or AccessKey Creation
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1059.009
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
AWS Key Pair Import Activity
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
AWS Root Credentials
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.initial-access
attack.persistence
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
AWS Route 53 Domain Transfer Lock Disabled
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.credential-access
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
AWS Route 53 Domain Transferred to Another Account
calendar
Oct 23, 2025
·
attack.persistence
attack.credential-access
attack.privilege-escalation
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
AWS SAML Provider Deletion Activity
calendar
Oct 23, 2025
·
attack.t1078.004
attack.privilege-escalation
attack.defense-evasion
attack.initial-access
attack.persistence
attack.t1531
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
AWS STS AssumeRole Misuse
calendar
Oct 23, 2025
·
attack.lateral-movement
attack.privilege-escalation
attack.defense-evasion
attack.t1548
attack.t1550
attack.t1550.001
·
Share on:
twitter
facebook
linkedin
copy
AWS STS GetSessionToken Misuse
calendar
Oct 23, 2025
·
attack.lateral-movement
attack.privilege-escalation
attack.defense-evasion
attack.t1548
attack.t1550
attack.t1550.001
·
Share on:
twitter
facebook
linkedin
copy
AWS Successful Console Login Without MFA
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
AWS Suspicious SAML Activity
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.initial-access
attack.lateral-movement
attack.persistence
attack.privilege-escalation
attack.t1078
attack.t1548
attack.t1550
attack.t1550.001
·
Share on:
twitter
facebook
linkedin
copy
AWS User Login Profile Was Modified
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Azure AD Only Single Factor Authentication Required
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.credential-access
attack.t1078.004
attack.t1556.006
·
Share on:
twitter
facebook
linkedin
copy
Azure Domain Federation Settings Modified
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Azure Kubernetes Admission Controller
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.initial-access
attack.defense-evasion
attack.persistence
attack.t1078
attack.credential-access
attack.t1552
attack.t1552.007
·
Share on:
twitter
facebook
linkedin
copy
Azure Login Bypassing Conditional Access Policies
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.defense-evasion
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Azure Subscription Permission Elevation Via ActivityLogs
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Azure Subscription Permission Elevation Via AuditLogs
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Azure Unusual Authentication Interruption
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket User Login Failure
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.defense-evasion
attack.credential-access
attack.t1078.004
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Bitlocker Key Retrieval
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.defense-evasion
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Bulk Deletion Changes To Privileged Account Permissions
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Bypass UAC Using Event Viewer
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.010
·
Share on:
twitter
facebook
linkedin
copy
Bypass UAC via Fodhelper.exe
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
CA Policy Removed by Non Approved Actor
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.credential-access
attack.defense-evasion
attack.persistence
attack.t1548
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
CA Policy Updated by Non Approved Actor
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.credential-access
attack.defense-evasion
attack.persistence
attack.t1548
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
Certificate-Based Authentication Enabled
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.credential-access
attack.persistence
attack.privilege-escalation
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
Change Default File Association To Executable Via Assoc
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.001
·
Share on:
twitter
facebook
linkedin
copy
Change Default File Association Via Assoc
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.001
·
Share on:
twitter
facebook
linkedin
copy
Change to Authentication Method
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.credential-access
attack.t1556
attack.persistence
attack.defense-evasion
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Changes To PIM Settings
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.privilege-escalation
attack.persistence
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Changing Existing Service ImagePath Value Via Reg.EXE
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
ChromeLoader Malware Execution
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
attack.t1059.001
attack.t1176
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Cisco Local Accounts
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1136.001
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Cisco Modify Configuration
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.impact
attack.t1490
attack.t1505
attack.t1565.002
attack.t1053
·
Share on:
twitter
facebook
linkedin
copy
Classes Autorun Keys Modification
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
CobaltStrike Service Installations - Security
calendar
Oct 23, 2025
·
attack.persistence
attack.execution
attack.privilege-escalation
attack.lateral-movement
attack.t1021.002
attack.t1543.003
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
CobaltStrike Service Installations - System
calendar
Oct 23, 2025
·
attack.persistence
attack.execution
attack.privilege-escalation
attack.lateral-movement
attack.t1021.002
attack.t1543.003
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
Code Injection by ld.so Preload
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.006
·
Share on:
twitter
facebook
linkedin
copy
CodeIntegrity - Blocked Driver Load With Revoked Certificate
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543
·
Share on:
twitter
facebook
linkedin
copy
CodeIntegrity - Blocked Image/Driver Load For Policy Violation
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543
·
Share on:
twitter
facebook
linkedin
copy
COM Hijack via Sdclt
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1546
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
COM Hijacking via TreatAs
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.015
·
Share on:
twitter
facebook
linkedin
copy
COM Object Hijacking Via Modification Of Default System CLSID Default Value
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.015
·
Share on:
twitter
facebook
linkedin
copy
Common Autorun Keys Modification
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Commvault QLogin with PublicSharingUser and GUID Password (CVE-2025-57788)
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078.001
detection.emerging-threats
cve.2025-57788
·
Share on:
twitter
facebook
linkedin
copy
Control Panel Items
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.defense-evasion
attack.t1218.002
attack.persistence
attack.t1546
·
Share on:
twitter
facebook
linkedin
copy
CosmicDuke Service Installation
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1543.003
attack.t1569.002
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Created Files by Microsoft Sync Center
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.t1055
attack.t1218
attack.execution
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Creation Exe for Service with Unquoted Path
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.009
·
Share on:
twitter
facebook
linkedin
copy
Creation of WerFault.exe/Wer.dll in Unusual Folder
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Credential Dumping Attempt Via Svchost
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
CurrentControlSet Autorun Keys Modification
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
CurrentVersion Autorun Keys Modification
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
CurrentVersion NT Autorun Keys Modification
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
CVE-2022-24527 Microsoft Connected Cache LPE
calendar
Oct 23, 2025
·
attack.execution
attack.privilege-escalation
attack.t1059.001
cve.2022-24527
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Default RDP Port Changed to Non Standard Port
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.010
·
Share on:
twitter
facebook
linkedin
copy
Defrag Deactivation
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
attack.s0111
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Defrag Deactivation - Security
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053
attack.s0111
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Deny Service Access Using Security Descriptor Tampering Via Sc.EXE
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Device Registration or Join Without MFA
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.defense-evasion
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
DHCP Callout DLL Installation
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
DHCP Server Error Failed Loading the CallOut DLL
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
DHCP Server Loaded the CallOut DLL
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Diamond Sleet APT DLL Sideloading Indicators
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Direct Autorun Keys Modification
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Disable ASLR Via Personality Syscall - Linux
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1562.001
attack.t1055.009
·
Share on:
twitter
facebook
linkedin
copy
DLL Execution Via Register-cimprovider.exe
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574
·
Share on:
twitter
facebook
linkedin
copy
DLL Load via LSASS
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1547.008
·
Share on:
twitter
facebook
linkedin
copy
DLL Names Used By SVR For GraphicalProton Backdoor
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
DLL Sideloading by VMware Xfer Utility
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Dllhost.EXE Execution Anomaly
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
DNS Server Error Failed Loading the ServerLevelPluginDLL
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
DotNet CLR DLL Loaded By Scripting Applications
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.execution
attack.privilege-escalation
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Enabled User Right in AD to Control User Objects
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
ESXi Admin Permission Assigned To Account Via ESXCLI
calendar
Oct 23, 2025
·
attack.persistence
attack.execution
attack.privilege-escalation
attack.t1059.012
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Exploiting SetupComplete.cmd CVE-2019-1378
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1068
attack.execution
attack.t1059.003
attack.t1574
cve.2019-1378
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Explorer NOUACCHECK Flag
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
External Remote RDP Logon from Public IP
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.credential-access
attack.t1133
attack.t1078
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
External Remote SMB Logon from Public IP
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.credential-access
attack.t1133
attack.t1078
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Failed Authentications From Countries You Do Not Operate Out Of
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.credential-access
attack.t1078.004
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Failed Logon From Public IP
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.initial-access
attack.persistence
attack.t1078
attack.t1190
attack.t1133
·
Share on:
twitter
facebook
linkedin
copy
Fax Service DLL Search Order Hijack
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
File Creation In Suspicious Directory By Msdt.EXE
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
cve.2022-30190
·
Share on:
twitter
facebook
linkedin
copy
Forest Blizzard APT - Custom Protocol Handler Creation
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Forest Blizzard APT - Custom Protocol Handler DLL Registry Set
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
GCP Break-glass Container Workload Deployed
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Github Outside Collaborator Detected
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.collection
attack.t1098.001
attack.t1098.003
attack.t1213.003
·
Share on:
twitter
facebook
linkedin
copy
Github SSH Certificate Configuration Changed
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Google Cloud Kubernetes Admission Controller
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.initial-access
attack.defense-evasion
attack.persistence
attack.t1078
attack.credential-access
attack.t1552
attack.t1552.007
·
Share on:
twitter
facebook
linkedin
copy
Google Workspace Granted Domain API Access
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Google Workspace User Granted Admin Privileges
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Granting Of Permissions To An Account
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098.003
·
Share on:
twitter
facebook
linkedin
copy
Group Policy Abuse for Privilege Addition
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1484.001
·
Share on:
twitter
facebook
linkedin
copy
Guest Account Enabled Via Sysadminctl
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078
attack.t1078.001
·
Share on:
twitter
facebook
linkedin
copy
Guest User Invited By Non Approved Inviters
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.defense-evasion
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Guest Users Invited To Tenant By Non Approved Inviters
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
HackTool - CACTUSTORCH Remote Thread Creation
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.execution
attack.t1055.012
attack.t1059.005
attack.t1059.007
attack.t1218.005
·
Share on:
twitter
facebook
linkedin
copy
HackTool - CrackMapExec Execution Patterns
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.t1047
attack.t1053
attack.t1059.003
attack.t1059.001
attack.s0106
·
Share on:
twitter
facebook
linkedin
copy
HackTool - DInjector PowerShell Cradle Execution
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
HackTool - HollowReaper Execution
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055.012
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Koh Default Named Pipe
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.credential-access
attack.t1528
attack.t1134.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - LittleCorporal Generated Maldoc Injection
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.execution
attack.privilege-escalation
attack.t1204.002
attack.t1055.003
·
Share on:
twitter
facebook
linkedin
copy
HackTool - NoFilter Execution
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1134
attack.t1134.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Potential CobaltStrike Process Injection
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - PPID Spoofing SelectMyParent Tool Execution
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1134.004
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SharPersist Execution
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SharpUp PrivEsc Tool Execution
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.discovery
attack.execution
attack.t1615
attack.t1569.002
attack.t1574.005
·
Share on:
twitter
facebook
linkedin
copy
HAFNIUM Exchange Exploitation Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1546
attack.t1053
attack.g0125
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Increased Failed Authentications Of Any Type
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.defense-evasion
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Injected Browser Process Spawning Rundll32 - GuLoader Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Interactive AT Job
calendar
Oct 23, 2025
·
attack.persistence
attack.execution
attack.privilege-escalation
attack.t1053.002
·
Share on:
twitter
facebook
linkedin
copy
Internet Explorer Autorun Keys Modification
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Invalid PIM License
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
ISATAP Router Address Was Set
calendar
Oct 23, 2025
·
attack.impact
attack.credential-access
attack.collection
attack.initial-access
attack.privilege-escalation
attack.execution
attack.t1557
attack.t1565.002
·
Share on:
twitter
facebook
linkedin
copy
Kapeka Backdoor Autorun Persistence
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Kapeka Backdoor Persistence Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
KrbRelayUp Service Installation
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543
·
Share on:
twitter
facebook
linkedin
copy
Kubernetes Admission Controller Modification
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.initial-access
attack.defense-evasion
attack.persistence
attack.t1078
attack.credential-access
attack.t1552
attack.t1552.007
·
Share on:
twitter
facebook
linkedin
copy
Launch Agent/Daemon Execution Via Launchctl
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1569.001
attack.t1543.001
attack.t1543.004
·
Share on:
twitter
facebook
linkedin
copy
Lazarus APT DLL Sideloading Activity
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.persistence
attack.t1574.001
attack.g0032
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Leviathan Registry Key Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Linux Capabilities Discovery
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.collection
attack.privilege-escalation
attack.t1123
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Linux Doas Conf File Creation
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Linux Doas Tool Execution
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Login to Disabled Account
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Logon from a Risky IP Address
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Lummac Stealer Activity - Execution Of More.com And Vbc.exe
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Malicious Driver Load
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Malicious Driver Load By Name
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Malicious Usage Of IMDS Credentials Outside Of AWS Infrastructure
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.initial-access
attack.persistence
attack.t1078
attack.t1078.002
·
Share on:
twitter
facebook
linkedin
copy
ManageEngine Endpoint Central Dctask64.EXE Potential Abuse
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055.001
·
Share on:
twitter
facebook
linkedin
copy
Measurable Increase Of Successful Authentications
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.defense-evasion
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Meterpreter or Cobalt Strike Getsystem Service Installation - Security
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1134.001
attack.t1134.002
·
Share on:
twitter
facebook
linkedin
copy
Meterpreter or Cobalt Strike Getsystem Service Installation - System
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1134.001
attack.t1134.002
·
Share on:
twitter
facebook
linkedin
copy
Microsoft 365 - Impossible Travel Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Defender Blocked from Loading Unsigned DLL
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Sync Center Suspicious Network Connections
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.t1055
attack.t1218
attack.execution
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
MITRE BZAR Indicators for Execution
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.t1047
attack.t1053.002
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
MITRE BZAR Indicators for Persistence
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.004
·
Share on:
twitter
facebook
linkedin
copy
Modification of ld.so.preload
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.006
·
Share on:
twitter
facebook
linkedin
copy
Modifying Crontab
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.003
·
Share on:
twitter
facebook
linkedin
copy
MSSQL Extended Stored Procedure Backdoor Maggie
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Multifactor Authentication Denied
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.credential-access
attack.t1078.004
attack.t1110
attack.t1621
·
Share on:
twitter
facebook
linkedin
copy
Multifactor Authentication Interrupted
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.credential-access
attack.t1078.004
attack.t1110
attack.t1621
·
Share on:
twitter
facebook
linkedin
copy
Narrator's Feedback-Hub Persistence
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Network Connection Initiated Via Notepad.EXE
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.command-and-control
attack.execution
attack.defense-evasion
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
New ActiveScriptEventConsumer Created Via Wmic.EXE
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.003
·
Share on:
twitter
facebook
linkedin
copy
New CA Policy by Non-approved Actor
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
New Custom Shim Database Created
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.009
·
Share on:
twitter
facebook
linkedin
copy
New DLL Added to AppCertDlls Registry Key
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.009
·
Share on:
twitter
facebook
linkedin
copy
New DLL Added to AppInit_DLLs Registry Key
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.010
·
Share on:
twitter
facebook
linkedin
copy
New DNS ServerLevelPluginDll Installed
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
New DNS ServerLevelPluginDll Installed Via Dnscmd.EXE
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
New Netsh Helper DLL Registered From A Suspicious Location
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.007
·
Share on:
twitter
facebook
linkedin
copy
New Outlook Macro Created
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.command-and-control
attack.t1137
attack.t1008
attack.t1546
·
Share on:
twitter
facebook
linkedin
copy
New PDQDeploy Service - Client Side
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
New PDQDeploy Service - Server Side
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
New Root Certificate Authority Added
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.credential-access
attack.persistence
attack.privilege-escalation
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
New RUN Key Pointing to Suspicious Folder
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Number Of Resource Creation Or Deployment Activities
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Office Autorun Keys Modification
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.defense-evasion
attack.t1112
attack.command-and-control
attack.t1071.004
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Registry Persistence
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.defense-evasion
attack.t1112
attack.command-and-control
attack.t1071.004
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Schedule Task Persistence - Security
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.defense-evasion
attack.t1112
attack.command-and-control
attack.t1071.004
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
OilRig APT Schedule Task Persistence - System
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.g0049
attack.t1053.005
attack.s0111
attack.t1543.003
attack.defense-evasion
attack.t1112
attack.command-and-control
attack.t1071.004
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Okta Admin Role Assigned to an User or Group
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098.003
·
Share on:
twitter
facebook
linkedin
copy
Okta Identity Provider Created
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098.001
·
Share on:
twitter
facebook
linkedin
copy
Okta New Admin Console Behaviours
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - SSH Login Attempt
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.initial-access
attack.lateral-movement
attack.persistence
attack.t1133
attack.t1021
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - SSH New Connection Attempt
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.initial-access
attack.lateral-movement
attack.persistence
attack.t1133
attack.t1021
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - Telnet Login Attempt
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.command-and-control
attack.t1133
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Operation Wocao Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.discovery
attack.t1012
attack.defense-evasion
attack.t1036.004
attack.t1027
attack.execution
attack.t1053.005
attack.t1059.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Operation Wocao Activity - Security
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.discovery
attack.t1012
attack.defense-evasion
attack.t1036.004
attack.t1027
attack.execution
attack.t1053.005
attack.t1059.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Outlook Macro Execution Without Warning Setting Enabled
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.command-and-control
attack.t1137
attack.t1008
attack.t1546
·
Share on:
twitter
facebook
linkedin
copy
Password Change on Directory Service Restore Mode (DSRM) Account
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Password Reset By User Account
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.initial-access
attack.defense-evasion
attack.persistence
attack.credential-access
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Password Set to Never Expire via WMI
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1047
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Persistence and Execution at Scale via GPO Scheduled Task
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.lateral-movement
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Persistence Via Cron Files
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.003
·
Share on:
twitter
facebook
linkedin
copy
Persistence Via Sticky Key Backdoor
calendar
Oct 23, 2025
·
attack.persistence
attack.t1546.008
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Persistence Via Sudoers Files
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.003
·
Share on:
twitter
facebook
linkedin
copy
PIM Alert Setting Changes To Disabled
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
PIM Approvals And Deny Elevation
calendar
Oct 23, 2025
·
attack.persistence
attack.initial-access
attack.defense-evasion
attack.privilege-escalation
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Pingback Backdoor Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Pingback Backdoor DLL Loading Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Pingback Backdoor File Indicators
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential ACTINIUM Persistence Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053
attack.t1053.005
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential appverifUI.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential AVKkid.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Azure Browser SSO Abuse
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential BearLPE Exploitation
calendar
Oct 23, 2025
·
attack.persistence
attack.execution
attack.privilege-escalation
attack.t1053.005
car.2013-08-001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CobaltStrike Service Installations - Registry
calendar
Oct 23, 2025
·
attack.persistence
attack.execution
attack.privilege-escalation
attack.lateral-movement
attack.t1021.002
attack.t1543.003
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
Potential COM Object Hijacking Via TreatAs Subkey - Registry
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.015
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Injection Or Execution Using Tracker.exe
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of DbgModel.DLL
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of KeyScramblerIE.DLL Via KeyScrambler.EXE
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of MpSvc.DLL
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of MsCorSvc.DLL
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Using Coregen.exe
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1218
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Via DeviceEnroller.EXE
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Via VMware Xfer
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential EACore.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Edputil.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Exploitation of CrushFTP RCE Vulnerability (CVE-2025-54309)
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.initial-access
attack.execution
attack.t1059.001
attack.t1059.003
attack.t1068
attack.t1190
cve.2025-54309
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Goopdate.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Initial Access via DLL Search Order Hijacking
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1566
attack.t1566.001
attack.initial-access
attack.t1574
attack.t1574.001
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
Potential Iviewers.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential KamiKakaBot Activity - Winlogon Shell Persistence
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Kerberos Coercion by Spoofing SPNs via DNS Manipulation
calendar
Oct 23, 2025
·
attack.collection
attack.credential-access
attack.t1557.003
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Potential Linux Process Code Injection Via DD Utility
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055.009
·
Share on:
twitter
facebook
linkedin
copy
Potential Meterpreter/CobaltStrike Activity
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1134.001
attack.t1134.002
·
Share on:
twitter
facebook
linkedin
copy
Potential MFA Bypass Using Legacy Client Authentication
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.credential-access
attack.t1078.004
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Potential Mfdetours.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Mpclient.DLL Sideloading
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Mpclient.DLL Sideloading Via Defender Binaries
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Notepad++ CVE-2025-49144 Exploitation
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.defense-evasion
attack.t1574.008
cve.2025-49144
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Attempt Via Existing Service Tampering
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.t1543.003
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Attempt Via Run Keys Using Reg.EXE
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Using DebugPath
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.015
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via App Paths Default Property
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.012
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via AppCompat RegisterAppRestart Layer
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.011
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Logon Scripts - CommandLine
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1037.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Logon Scripts - Registry
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.t1037.001
attack.persistence
attack.lateral-movement
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Microsoft Compatibility Appraiser
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Netsh Helper DLL - Registry
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.007
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Outlook LoadMacroProviderOnBoot Setting
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.command-and-control
attack.t1137
attack.t1008
attack.t1546
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via PlistBuddy
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1543.001
attack.t1543.004
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Powershell Search Order Hijacking - Task
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Scrobj.dll COM Hijacking
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.015
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Shim Database In Uncommon Location
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.011
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Shim Database Modification
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.011
·
Share on:
twitter
facebook
linkedin
copy
Potential Pikabot Hollowing Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055.012
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential PlugX Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.s0013
attack.defense-evasion
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Privilege Escalation via Local Kerberos Relay over LDAP
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.credential-access
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Potential Privilege Escalation via Service Permissions Weakness
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Potential Process Injection Via Msra.EXE
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Potential PSFactoryBuffer COM Hijacking
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.015
·
Share on:
twitter
facebook
linkedin
copy
Potential Python DLL SideLoading
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Raspberry Robin Aclui Dll SideLoading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Rcdll.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Registry Persistence Attempt Via DbgManagedDebugger
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.t1574
·
Share on:
twitter
facebook
linkedin
copy
Potential Registry Persistence Attempt Via Windows Telemetry
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Potential RipZip Attack on Startup Folder
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547
·
Share on:
twitter
facebook
linkedin
copy
Potential RjvPlatform.DLL Sideloading From Default Location
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential RjvPlatform.DLL Sideloading From Non-Default Location
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential RoboForm.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Ryuk Ransomware Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential ShellDispatch.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential SmadHook.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential SolidPDFCreator.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential SSH Tunnel Persistence Install Using A Scheduled Task
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.t1053.005
attack.command-and-control
·
Share on:
twitter
facebook
linkedin
copy
Potential Startup Shortcut Persistence Via PowerShell.EXE
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Activity Using SeCEdit
calendar
Oct 23, 2025
·
attack.collection
attack.discovery
attack.persistence
attack.defense-evasion
attack.credential-access
attack.privilege-escalation
attack.t1562.002
attack.t1547.001
attack.t1505.005
attack.t1556.002
attack.t1562
attack.t1574.007
attack.t1564.002
attack.t1546.008
attack.t1546.007
attack.t1547.014
attack.t1547.010
attack.t1547.002
attack.t1557
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
Potential Vivaldi_elf.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Waveedit.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential WWlib.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Child Process of KeyScrambler.exe
calendar
Oct 23, 2025
·
attack.persistence
attack.execution
attack.defense-evasion
attack.privilege-escalation
attack.t1203
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Powershell Create Scheduled Task
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Powershell LocalAccount Manipulation
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Web Access Feature Enabled Via DISM
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Powershell WMI Persistence
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1546.003
·
Share on:
twitter
facebook
linkedin
copy
Powerview Add-DomainObjectAcl DCSync AD Extend Right
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Privileged Account Creation
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Privileged User Has Been Created
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1136.001
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
ProcessHacker Privilege Elevation
calendar
Oct 23, 2025
·
attack.persistence
attack.execution
attack.privilege-escalation
attack.t1543.003
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
PUA - Process Hacker Driver Load
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
cve.2021-21551
attack.t1543
·
Share on:
twitter
facebook
linkedin
copy
PUA - System Informer Driver Load
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543
·
Share on:
twitter
facebook
linkedin
copy
PwnKit Local Privilege Escalation
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.001
·
Share on:
twitter
facebook
linkedin
copy
Regedit as Trusted Installer
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Registry Persistence Mechanisms in Recycle Bin
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547
·
Share on:
twitter
facebook
linkedin
copy
Registry Persistence via Explorer Run Key
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Registry-Free Process Scope COR_PROFILER
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.t1574.012
·
Share on:
twitter
facebook
linkedin
copy
Regsvr32 DLL Execution With Uncommon Extension
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool Services Have Been Installed - Security
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.t1543.003
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool Services Have Been Installed - System
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.t1543.003
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Schedule Task Lateral Movement via ATSvc
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.lateral-movement
attack.execution
attack.persistence
attack.t1053
attack.t1053.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Schedule Task Lateral Movement via ITaskSchedulerService
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.lateral-movement
attack.t1053
attack.t1053.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Schedule Task Lateral Movement via SASec
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.lateral-movement
attack.execution
attack.persistence
attack.t1053
attack.t1053.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Task Creation via ATSVC Named Pipe
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.lateral-movement
attack.persistence
car.2013-05-004
car.2015-04-001
attack.t1053.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Task Creation via ATSVC Named Pipe - Zeek
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.lateral-movement
attack.persistence
car.2013-05-004
car.2015-04-001
attack.t1053.002
·
Share on:
twitter
facebook
linkedin
copy
Renamed Vmnat.exe Execution
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Renamed ZOHO Dctask64 Execution
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1036
attack.t1055.001
attack.t1202
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Roles Activated Too Frequently
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Roles Activation Doesn't Require MFA
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Roles Are Not Being Used
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Roles Assigned Outside PIM
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Root Account Enable Via Dsenableroot
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1078
attack.t1078.001
attack.t1078.003
attack.initial-access
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
RottenPotato Like Attack Pattern
calendar
Oct 23, 2025
·
attack.collection
attack.privilege-escalation
attack.credential-access
attack.t1557.001
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Task Creation Masquerading as System Processes
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
attack.defense-evasion
attack.t1036.004
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Task Creation with Curl and PowerShell Execution Combo
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
attack.defense-evasion
attack.t1218
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Task Executed From A Suspicious Location
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Task Executed Uncommon LOLBIN
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Task Executing Encoded Payload from Registry
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Task Executing Payload from Registry
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Task/Job At
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.002
·
Share on:
twitter
facebook
linkedin
copy
Scheduled TaskCache Change by Uncommon Program
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Schtasks Creation Or Modification With SYSTEM Privileges
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Schtasks From Suspicious Folders
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
SCM Database Privileged Operation
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Sdclt Child Processes
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Security Support Provider (SSP) Added to LSA Configuration
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.005
·
Share on:
twitter
facebook
linkedin
copy
Serpent Backdoor Payload Execution Via Scheduled Task
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
attack.t1059.006
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Service Installed By Unusual Client - Security
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543
·
Share on:
twitter
facebook
linkedin
copy
Service Installed By Unusual Client - System
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543
·
Share on:
twitter
facebook
linkedin
copy
Service Registry Permissions Weakness Check
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.t1574.011
stp.2a
·
Share on:
twitter
facebook
linkedin
copy
Service Reload or Start - Linux
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1543.002
·
Share on:
twitter
facebook
linkedin
copy
Session Manager Autorun Keys Modification
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
attack.t1546.009
·
Share on:
twitter
facebook
linkedin
copy
Setuid and Setgid
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1548.001
·
Share on:
twitter
facebook
linkedin
copy
Setup16.EXE Execution With Custom .Lst File
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.005
·
Share on:
twitter
facebook
linkedin
copy
Shell Open Registry Keys Manipulation
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
attack.t1546.001
·
Share on:
twitter
facebook
linkedin
copy
Sign-in Failure Due to Conditional Access Requirements Not Met
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.credential-access
attack.t1110
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Sign-ins by Unknown Devices
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.defense-evasion
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Sign-ins from Non-Compliant Devices
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.defense-evasion
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Sliver C2 Default Service Installation
calendar
Oct 23, 2025
·
attack.persistence
attack.execution
attack.privilege-escalation
attack.t1543.003
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
Small Sieve Malware CommandLine Indicator
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Special File Creation via Mknod Syscall
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Stale Accounts In A Privileged Role
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Startup Folder File Write
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Startup/Logon Script Added to Group Policy Object
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1484.001
attack.t1547
·
Share on:
twitter
facebook
linkedin
copy
StoneDrill Service Install
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.g0064
attack.t1543.003
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Successful Authentications From Countries You Do Not Operate Out Of
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.credential-access
attack.t1078.004
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Sudo Privilege Escalation CVE-2019-14287
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1068
attack.t1548.003
cve.2019-14287
·
Share on:
twitter
facebook
linkedin
copy
Sudo Privilege Escalation CVE-2019-14287 - Builtin
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1068
attack.t1548.003
cve.2019-14287
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Autorun Registry Modified via WMI
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1547.001
attack.t1047
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Child Process Created as System
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1134.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Command Patterns In Scheduled Task Creation
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Computer Account Name Change CVE-2021-42287
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.t1036
attack.t1098
cve.2021-42287
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Computer Machine Password by PowerShell
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Suspicious desktop.ini Action
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.009
·
Share on:
twitter
facebook
linkedin
copy
Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing
calendar
Oct 23, 2025
·
attack.collection
attack.credential-access
attack.persistence
attack.privilege-escalation
attack.t1557.001
attack.t1187
·
Share on:
twitter
facebook
linkedin
copy
Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing - Network
calendar
Oct 23, 2025
·
attack.collection
attack.credential-access
attack.persistence
attack.privilege-escalation
attack.t1557.001
attack.t1187
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Driver Install by pnputil.exe
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Encoded Scripts in a WMI Consumer
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.t1047
attack.persistence
attack.t1546.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Get-Variable.exe Creation
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546
attack.defense-evasion
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Suspicious GrpConv Execution
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547
·
Share on:
twitter
facebook
linkedin
copy
Suspicious GUP Usage
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Modification Of Scheduled Tasks
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Outlook Macro Created
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.command-and-control
attack.t1137
attack.t1008
attack.t1546
·
Share on:
twitter
facebook
linkedin
copy
Suspicious PowerShell In Registry Run Keys
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Printer Driver Empty Manufacturer
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574
cve.2021-1675
·
Share on:
twitter
facebook
linkedin
copy
Suspicious RazerInstaller Explorer Subprocess
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1553
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Remote Logon with Explicit Credentials
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.defense-evasion
attack.t1078
attack.lateral-movement
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Run Key from Download
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Rundll32 Invoking Inline VBScript
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Scheduled Task Creation Involving Temp Folder
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Scheduled Task Creation via Masqueraded XML File
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.defense-evasion
attack.persistence
attack.t1036.005
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Scheduled Task Name As GUID
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Scheduled Task Write to System32 Tasks
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.t1053
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Schtasks Execution AppData Folder
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1053.005
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Schtasks Schedule Type With High Privileges
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Schtasks Schedule Types
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious ScreenSave Change by Reg.exe
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1546.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Screensaver Binary File Creation
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Service DACL Modification Via Set-Service Cmdlet
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Shim Database Patching Activity
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.011
·
Share on:
twitter
facebook
linkedin
copy
Suspicious SignIns From A Non Registered Device
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.defense-evasion
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Startup Folder Persistence
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.t1204.002
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Unsigned Thor Scanner Execution
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Userinit Child Process
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Suspicious VBScript UN2452 Pattern
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Sysinternals PsService Execution
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.discovery
attack.persistence
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Sysinternals PsSuspend Execution
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.discovery
attack.persistence
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
System Scripts Autorun Keys Modification
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Systemd Service Creation
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1543.002
·
Share on:
twitter
facebook
linkedin
copy
TAIDOOR RAT DLL Load
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.execution
attack.t1055.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Tasks Folder Evasion
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.execution
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Temporary Access Pass Added To An Account
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.initial-access
attack.defense-evasion
attack.persistence
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Too Many Global Admins
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Triple Cross eBPF Rootkit Default Persistence
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.defense-evasion
attack.t1053.003
·
Share on:
twitter
facebook
linkedin
copy
Trusted Path Bypass via Windows Directory Spoofing
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.007
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
TrustedPath UAC Bypass Pattern
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Turla Group Commands May 2020
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.g0010
attack.execution
attack.t1059.001
attack.t1053.005
attack.t1027
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Turla PNG Dropper Service
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.g0010
attack.t1543.003
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Turla Service Install
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.g0010
attack.t1543.003
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass via Windows Firewall Snap-In Hijack
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Userinit Child Process
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.t1037.001
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Unix Shell Configuration Modification
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.004
·
Share on:
twitter
facebook
linkedin
copy
Unsigned Binary Loaded From Suspicious Location
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Unsigned Mfdetours.DLL Sideloading
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Unsigned Module Loaded by ClickOnce Application
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.persistence
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Use Of Hidden Paths Or Files
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Use of Legacy Authentication Protocols
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.credential-access
attack.t1078.004
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
User Access Blocked by Azure Conditional Access
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.credential-access
attack.initial-access
attack.t1110
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
User Added To Admin Group Via Dscl
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.initial-access
attack.privilege-escalation
attack.t1078.003
·
Share on:
twitter
facebook
linkedin
copy
User Added To Admin Group Via DseditGroup
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.initial-access
attack.privilege-escalation
attack.t1078.003
·
Share on:
twitter
facebook
linkedin
copy
User Added To Admin Group Via Sysadminctl
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.initial-access
attack.privilege-escalation
attack.t1078.003
·
Share on:
twitter
facebook
linkedin
copy
User Added to an Administrator's Azure AD Role
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1098.003
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
User Added To Group With CA Policy Modification Access
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.credential-access
attack.defense-evasion
attack.persistence
attack.t1548
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
User Added To Highly Privileged Group
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
User Added to Local Administrator Group
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
attack.privilege-escalation
attack.t1078
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
User Added to Local Administrators Group
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
User Added To Privilege Role
calendar
Oct 23, 2025
·
attack.persistence
attack.initial-access
attack.privilege-escalation
attack.defense-evasion
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
User Couldn't Call a Privileged Service 'LsaRegisterLogonProcess'
calendar
Oct 23, 2025
·
attack.credential-access
attack.lateral-movement
attack.privilege-escalation
attack.t1558.003
·
Share on:
twitter
facebook
linkedin
copy
User Removed From Group With CA Policy Modification Access
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.credential-access
attack.defense-evasion
attack.persistence
attack.t1548
attack.t1556
·
Share on:
twitter
facebook
linkedin
copy
User State Changed From Guest To Member
calendar
Oct 23, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.initial-access
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Users Added to Global or Device Admin Roles
calendar
Oct 23, 2025
·
attack.persistence
attack.initial-access
attack.defense-evasion
attack.privilege-escalation
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Users Authenticating To Other Azure AD Tenants
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.initial-access
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Using SettingSyncHost.exe as LOLBin
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.defense-evasion
attack.t1574.008
·
Share on:
twitter
facebook
linkedin
copy
VBScript Payload Stored in Registry
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Vulnerable Driver Load
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Vulnerable Driver Load By Name
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Vulnerable HackSys Extreme Vulnerable Driver Load
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Vulnerable Netlogon Secure Channel Connection Allowed
calendar
Oct 23, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548
·
Share on:
twitter
facebook
linkedin
copy
Vulnerable WinRing0 Driver Load
calendar
Oct 23, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Win Susp Computer Name Containing Samtheadmin
calendar
Oct 23, 2025
·
attack.initial-access
attack.defense-evasion
cve.2021-42278
cve.2021-42287
attack.persistence
attack.privilege-escalation
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Windows Event Log Access Tampering Via Registry
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1547.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Windows Network Access Suspicious desktop.ini Action
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.009
·
Share on:
twitter
facebook
linkedin
copy
Windows Terminal Profile Settings Modification By Uncommon Process
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.015
·
Share on:
twitter
facebook
linkedin
copy
WINEKEY Registry Modification
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547
·
Share on:
twitter
facebook
linkedin
copy
Winlogon Helper DLL
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.004
·
Share on:
twitter
facebook
linkedin
copy
Winlogon Notify Key Logon Persistence
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.004
·
Share on:
twitter
facebook
linkedin
copy
Winnti Malware HK University Campaign
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
attack.g0044
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Winnti Pipemon Characteristics
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
attack.g0044
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
WinRAR Creating Files in Startup Locations
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
WinSock2 Autorun Keys Modification
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
WMI Backdoor Exchange Transport Agent
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.003
·
Share on:
twitter
facebook
linkedin
copy
WMI Event Subscription
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1546.003
·
Share on:
twitter
facebook
linkedin
copy
WMI Persistence - Command Line Event Consumer
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.t1546.003
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
WMI Persistence - Script Event Consumer File Write
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.t1546.003
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Wow6432Node Classes Autorun Keys Modification
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Wow6432Node CurrentVersion Autorun Keys Modification
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Wow6432Node Windows NT CurrentVersion Autorun Keys Modification
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Writing Local Admin Share
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.lateral-movement
attack.t1546.002
·
Share on:
twitter
facebook
linkedin
copy
Xwizard.EXE Execution From Non-Default Location
calendar
Oct 23, 2025
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Linux Sudo Chroot Execution
calendar
Oct 19, 2025
·
attack.privilege-escalation
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Non-Standard Nsswitch.Conf Creation - Potential CVE-2025-32463 Exploitation
calendar
Oct 19, 2025
·
attack.privilege-escalation
attack.t1068
cve.2025-32463
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Rare Remote Thread Creation By Uncommon Source Image
calendar
Oct 18, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Account Tampering - Suspicious Failed Logon Reasons
calendar
Oct 17, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.initial-access
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
New Kernel Driver Via SC.EXE
calendar
Oct 9, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Antivirus Software DLL Sideloading
calendar
Oct 9, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of DBGCORE.DLL
calendar
Oct 9, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of DBGHELP.DLL
calendar
Oct 9, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential JLI.dll Side-Loading
calendar
Oct 9, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Process Creation Using Sysnative Folder
calendar
Oct 9, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
HackTool - CoercedPotato Execution
calendar
Oct 1, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Certificate Use With No Strong Mapping
calendar
Sep 22, 2025
·
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
KDC RC4-HMAC Downgrade CVE-2022-37966
calendar
Sep 22, 2025
·
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
New Service Creation Using Sc.EXE
calendar
Sep 22, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Service Installation Script
calendar
Aug 28, 2025
·
attack.persistence
attack.privilege-escalation
car.2013-09-005
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
New Federated Domain Added
calendar
Aug 14, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1484.002
·
Share on:
twitter
facebook
linkedin
copy
Remote Thread Creation By Uncommon Source Image
calendar
Jul 8, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Remote Thread Creation In Uncommon Target Image
calendar
Jul 8, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Sysmon as Execution Parent
calendar
Jul 8, 2025
·
attack.privilege-escalation
attack.t1068
cve.2022-41120
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Child Process Of Wermgr.EXE
calendar
Jul 1, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
HKTL - SharpSuccessor Privilege Escalation Tool Execution
calendar
Jun 12, 2025
·
attack.privilege-escalation
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Potential System DLL Sideloading From Non System Locations
calendar
Jun 4, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Container With A hostPath Mount Created
calendar
Jun 4, 2025
·
attack.t1611
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Potential Malicious Usage of CloudTrail System Manager
calendar
Jun 4, 2025
·
attack.privilege-escalation
attack.initial-access
attack.t1566
attack.t1566.002
·
Share on:
twitter
facebook
linkedin
copy
Privileged Container Deployed
calendar
Jun 4, 2025
·
attack.t1611
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Buffer Overflow Attempts
calendar
Jun 4, 2025
·
attack.t1068
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Kubernetes CronJob/Job Modification
calendar
Jun 2, 2025
·
attack.persistence
attack.privilege-escalation
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Kubernetes Rolebinding Modification
calendar
Jun 2, 2025
·
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Suspicious SQL Query
calendar
May 20, 2025
·
attack.exfiltration
attack.initial-access
attack.privilege-escalation
attack.persistence
attack.t1190
attack.t1505.001
·
Share on:
twitter
facebook
linkedin
copy
Windows LAPS Credential Dump From Entra ID
calendar
May 20, 2025
·
attack.privilege-escalation
attack.persistence
attack.t1098.005
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SharpDPAPI Execution
calendar
May 20, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1134.001
attack.t1134.003
·
Share on:
twitter
facebook
linkedin
copy
Kapeka Backdoor Scheduled Task Creation
calendar
May 20, 2025
·
attack.execution
attack.privilege-escalation
attack.persistence
attack.t1053.005
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Creation Of Non-Existent System DLL
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
DLL Search Order Hijackig Via Additional Space in Path
calendar
May 15, 2025
·
attack.persistence
attack.privilege-escalation
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
DLL Sideloading Of ShellChromeAPI.DLL
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Malicious DLL File Dropped in the Teams or OneDrive Folder
calendar
May 15, 2025
·
attack.persistence
attack.privilege-escalation
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Office DLL Sideload
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential 7za.DLL Sideloading
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential CCleanerDU.DLL Sideloading
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential CCleanerReactivator.DLL Sideloading
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Chrome Frame Helper DLL Sideloading
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of Libcurl.DLL Via GUP.EXE
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of Non-Existent DLLs From System Folders
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Via ClassicExplorer32.dll
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Via comctl32.dll
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Via JsSchHlp
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Libvlc.DLL Sideloading
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Wazuh Security Platform DLL Sideloading
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Third Party Software DLL Sideloading
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass With Fake DLL
calendar
May 15, 2025
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
VMGuestLib DLL Sideload
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
VMMap Signed Dbghelp.DLL Potential Sideloading
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
VMMap Unsigned Dbghelp.DLL Potential Sideloading
calendar
May 15, 2025
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - winPEAS Execution
calendar
Apr 25, 2025
·
attack.privilege-escalation
attack.discovery
attack.t1082
attack.t1087
attack.t1046
·
Share on:
twitter
facebook
linkedin
copy
UAC Notification Disabled
calendar
Apr 16, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Secure Desktop Prompt Disabled
calendar
Apr 16, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Process Access Rights For Target Image
calendar
Apr 16, 2025
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055.011
·
Share on:
twitter
facebook
linkedin
copy
AWS New Lambda Layer Attached
calendar
Apr 7, 2025
·
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Elevated System Shell Spawned From Uncommon Parent Location
calendar
Apr 7, 2025
·
attack.privilege-escalation
attack.defense-evasion
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Kubernetes Unauthorized or Unauthenticated Access
calendar
Mar 4, 2025
·
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2024-3400 Exploitation - Palo Alto GlobalProtect OS Command Injection
calendar
Mar 4, 2025
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.defense-evasion
cve.2024-3400
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2024-35250 Exploitation Activity
calendar
Feb 24, 2025
·
attack.privilege-escalation
attack.t1068
cve.2024-35250
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
New TimeProviders Registered With Uncommon DLL Name
calendar
Feb 3, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1547.003
·
Share on:
twitter
facebook
linkedin
copy
ServiceDll Hijack
calendar
Feb 3, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Global Permission Changed
calendar
Jan 6, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
New AWS Lambda Function URL Configuration Created
calendar
Dec 19, 2024
·
attack.initial-access
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Register new Logon Process by Rubeus
calendar
Dec 19, 2024
·
attack.lateral-movement
attack.privilege-escalation
attack.credential-access
attack.t1558.003
·
Share on:
twitter
facebook
linkedin
copy
CMSTP UAC Bypass via COM Object Access
calendar
Dec 1, 2024
·
attack.execution
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
attack.t1218.003
attack.g0069
car.2019-04-001
·
Share on:
twitter
facebook
linkedin
copy
Exploiting CVE-2019-1388
calendar
Dec 1, 2024
·
attack.privilege-escalation
attack.t1068
cve.2019-1388
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Possible Privilege Escalation via Weak Service Permissions
calendar
Dec 1, 2024
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2021-41379 Exploitation Attempt
calendar
Dec 1, 2024
·
attack.privilege-escalation
attack.t1068
cve.2021-41379
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential UAC Bypass Via Sdclt.EXE
calendar
Dec 1, 2024
·
attack.privilege-escalation
attack.defense-evasion
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious SYSTEM User Process Creation
calendar
Dec 1, 2024
·
attack.credential-access
attack.defense-evasion
attack.privilege-escalation
attack.t1134
attack.t1003
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Abusing Winsat Path Parsing - Process
calendar
Dec 1, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Tools Using ComputerDefaults
calendar
Dec 1, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using ChangePK and SLUI
calendar
Dec 1, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using Consent and Comctl32 - Process
calendar
Dec 1, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using Disk Cleanup
calendar
Dec 1, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using DismHost
calendar
Dec 1, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using IDiagnostic Profile
calendar
Dec 1, 2024
·
attack.execution
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using IEInstal - Process
calendar
Dec 1, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using MSConfig Token Modification - Process
calendar
Dec 1, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using NTFS Reparse Point - Process
calendar
Dec 1, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using PkgMgr and DISM
calendar
Dec 1, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using Windows Media Player - Process
calendar
Dec 1, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass WSReset
calendar
Dec 1, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
GCP Access Policy Deleted
calendar
Dec 1, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
Google Workspace Application Access Level Modified
calendar
Dec 1, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1098.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Processes Spawned by Java.EXE
calendar
Dec 1, 2024
·
attack.initial-access
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Impersonate Execution
calendar
Nov 25, 2024
·
attack.privilege-escalation
attack.defense-evasion
attack.t1134.001
attack.t1134.003
·
Share on:
twitter
facebook
linkedin
copy
HackTool - LocalPotato Execution
calendar
Nov 25, 2024
·
attack.defense-evasion
attack.privilege-escalation
cve.2023-21746
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SysmonEOP Execution
calendar
Nov 25, 2024
·
cve.2022-41120
attack.t1068
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
HackTool - UACMe Akagi Execution
calendar
Nov 25, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
PUA - Process Hacker Execution
calendar
Nov 25, 2024
·
attack.defense-evasion
attack.discovery
attack.persistence
attack.privilege-escalation
attack.t1622
attack.t1564
attack.t1543
·
Share on:
twitter
facebook
linkedin
copy
PUA - System Informer Execution
calendar
Nov 25, 2024
·
attack.persistence
attack.privilege-escalation
attack.discovery
attack.defense-evasion
attack.t1082
attack.t1564
attack.t1543
·
Share on:
twitter
facebook
linkedin
copy
App Assigned To Azure RBAC/Microsoft Entra Role
calendar
Nov 20, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1098.003
·
Share on:
twitter
facebook
linkedin
copy
HackTool - EfsPotato Named Pipe Creation
calendar
Nov 1, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
HackTool - WinPwn Execution
calendar
Oct 1, 2024
·
attack.credential-access
attack.defense-evasion
attack.discovery
attack.execution
attack.privilege-escalation
attack.t1046
attack.t1082
attack.t1106
attack.t1518
attack.t1548.002
attack.t1552.001
attack.t1555
attack.t1555.003
·
Share on:
twitter
facebook
linkedin
copy
HackTool - WinPwn Execution - ScriptBlock
calendar
Oct 1, 2024
·
attack.credential-access
attack.defense-evasion
attack.discovery
attack.execution
attack.privilege-escalation
attack.t1046
attack.t1082
attack.t1106
attack.t1518
attack.t1548.002
attack.t1552.001
attack.t1555
attack.t1555.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Process Hollowing Activity
calendar
Oct 1, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055.012
·
Share on:
twitter
facebook
linkedin
copy
Whoami.EXE Execution From Privileged Process
calendar
Oct 1, 2024
·
attack.privilege-escalation
attack.discovery
attack.t1033
·
Share on:
twitter
facebook
linkedin
copy
CVE-2021-1675 Print Spooler Exploitation Filename Pattern
calendar
Sep 13, 2024
·
attack.execution
attack.privilege-escalation
attack.resource-development
attack.t1587
cve.2021-1675
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
InstallerFileTakeOver LPE CVE-2021-41379 File Create Event
calendar
Sep 13, 2024
·
attack.privilege-escalation
attack.t1068
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential PrintNightmare Exploitation Attempt
calendar
Sep 13, 2024
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574
cve.2021-1675
·
Share on:
twitter
facebook
linkedin
copy
Windows Spooler Service Suspicious Binary Load
calendar
Sep 13, 2024
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574
cve.2021-1675
cve.2021-34527
·
Share on:
twitter
facebook
linkedin
copy
Diamond Sleet APT Scheduled Task Creation
calendar
Sep 2, 2024
·
attack.execution
attack.privilege-escalation
attack.persistence
attack.t1053.005
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Exploitation Indicators Of CVE-2023-20198
calendar
Sep 2, 2024
·
attack.privilege-escalation
attack.initial-access
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
HackTool - CoercedPotato Named Pipe Creation
calendar
Sep 2, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Abuse of Service Permissions to Hide Services Via Set-Service
calendar
Aug 12, 2024
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Abuse of Service Permissions to Hide Services Via Set-Service - PS
calendar
Aug 12, 2024
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Activity From Anonymous IP Address
calendar
Aug 12, 2024
·
attack.t1078
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
ADCS Certificate Template Configuration Vulnerability
calendar
Aug 12, 2024
·
attack.privilege-escalation
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
ADCS Certificate Template Configuration Vulnerability with Risky EKU
calendar
Aug 12, 2024
·
attack.privilege-escalation
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
App Granted Privileged Delegated Or App Permissions
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1098.003
·
Share on:
twitter
facebook
linkedin
copy
Application Using Device Code Authentication Flow
calendar
Aug 12, 2024
·
attack.t1078
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
Applications That Are Using ROPC Authentication Flow
calendar
Aug 12, 2024
·
attack.t1078
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
APT PRIVATELOG Image Load Pattern
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Atypical Travel
calendar
Aug 12, 2024
·
attack.t1078
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
Audit CVE Event
calendar
Aug 12, 2024
·
attack.execution
attack.t1203
attack.privilege-escalation
attack.t1068
attack.defense-evasion
attack.t1211
attack.credential-access
attack.t1212
attack.lateral-movement
attack.t1210
attack.impact
attack.t1499.004
·
Share on:
twitter
facebook
linkedin
copy
AWS Glue Development Endpoint Activity
calendar
Aug 12, 2024
·
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Azure AD Threat Intelligence
calendar
Aug 12, 2024
·
attack.t1078
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
Azure Kubernetes CronJob
calendar
Aug 12, 2024
·
attack.persistence
attack.t1053.003
attack.privilege-escalation
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Bypass UAC Using DelegateExecute
calendar
Aug 12, 2024
·
attack.privilege-escalation
attack.defense-evasion
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Bypass UAC Using SilentCleanup Task
calendar
Aug 12, 2024
·
attack.privilege-escalation
attack.defense-evasion
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Bypass UAC via CMSTP
calendar
Aug 12, 2024
·
attack.privilege-escalation
attack.defense-evasion
attack.t1548.002
attack.t1218.003
·
Share on:
twitter
facebook
linkedin
copy
Bypass UAC via WSReset.exe
calendar
Aug 12, 2024
·
attack.privilege-escalation
attack.defense-evasion
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Changes to Device Registration Policy
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1484
·
Share on:
twitter
facebook
linkedin
copy
Cisco BGP Authentication Failures
calendar
Aug 12, 2024
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.defense-evasion
attack.credential-access
attack.collection
attack.t1078
attack.t1110
attack.t1557
·
Share on:
twitter
facebook
linkedin
copy
Cisco LDP Authentication Failures
calendar
Aug 12, 2024
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.defense-evasion
attack.credential-access
attack.collection
attack.t1078
attack.t1110
attack.t1557
·
Share on:
twitter
facebook
linkedin
copy
CobaltStrike Named Pipe
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
CobaltStrike Named Pipe Pattern Regex
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
CobaltStrike Named Pipe Patterns
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055
stp.1k
·
Share on:
twitter
facebook
linkedin
copy
CodeIntegrity - Blocked Image Load With Revoked Certificate
calendar
Aug 12, 2024
·
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
CodeIntegrity - Disallowed File For Protected Processes Has Been Blocked
calendar
Aug 12, 2024
·
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
CodeIntegrity - Revoked Image Loaded
calendar
Aug 12, 2024
·
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
CodeIntegrity - Revoked Kernel Driver Loaded
calendar
Aug 12, 2024
·
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
CodeIntegrity - Unmet WHQL Requirements For Loaded Kernel Module
calendar
Aug 12, 2024
·
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
CodeIntegrity - Unsigned Image Loaded
calendar
Aug 12, 2024
·
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
CodeIntegrity - Unsigned Kernel Module Loaded
calendar
Aug 12, 2024
·
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
DiagTrackEoP Default Login Username
calendar
Aug 12, 2024
·
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Driver Load From A Temporary Directory
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Enabling COR Profiler Environment Variables
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.defense-evasion
attack.t1574.012
·
Share on:
twitter
facebook
linkedin
copy
Function Call From Undocumented COM Interface EditionUpgradeManager
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Github New Secret Created
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.initial-access
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Github Self Hosted Runner Changes Detected
calendar
Aug 12, 2024
·
attack.impact
attack.discovery
attack.collection
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.initial-access
attack.t1526
attack.t1213.003
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Google Cloud Kubernetes CronJob
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
HackTool - CrackMapExec Execution
calendar
Aug 12, 2024
·
attack.execution
attack.persistence
attack.privilege-escalation
attack.credential-access
attack.discovery
attack.t1047
attack.t1053
attack.t1059.003
attack.t1059.001
attack.t1110
attack.t1201
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Default PowerSploit/Empire Scheduled Task Creation
calendar
Aug 12, 2024
·
attack.execution
attack.persistence
attack.privilege-escalation
attack.s0111
attack.g0022
attack.g0060
car.2013-08-001
attack.t1053.005
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - DiagTrackEoP Default Named Pipe
calendar
Aug 12, 2024
·
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Empire PowerShell UAC Bypass
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
car.2019-04-001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Powerup Write Hijack DLL
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.defense-evasion
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SharpImpersonation Execution
calendar
Aug 12, 2024
·
attack.privilege-escalation
attack.defense-evasion
attack.t1134.001
attack.t1134.003
·
Share on:
twitter
facebook
linkedin
copy
Huawei BGP Authentication Failures
calendar
Aug 12, 2024
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.defense-evasion
attack.credential-access
attack.collection
attack.t1078
attack.t1110
attack.t1557
·
Share on:
twitter
facebook
linkedin
copy
Important Scheduled Task Deleted/Disabled
calendar
Aug 12, 2024
·
attack.execution
attack.privilege-escalation
attack.persistence
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Impossible Travel
calendar
Aug 12, 2024
·
attack.t1078
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
Juniper BGP Missing MD5
calendar
Aug 12, 2024
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.defense-evasion
attack.credential-access
attack.collection
attack.t1078
attack.t1110
attack.t1557
·
Share on:
twitter
facebook
linkedin
copy
LiveKD Driver Creation
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
LiveKD Driver Creation By Uncommon Process
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
LiveKD Kernel Memory Dump File Created
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Loading of Kernel Module via Insmod
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1547.006
·
Share on:
twitter
facebook
linkedin
copy
MacOS Emond Launch Daemon
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1546.014
·
Share on:
twitter
facebook
linkedin
copy
Malicious Named Pipe Created
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Malware Shellcode in Verclsid Target Process
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Mavinject Inject DLL Into Running Process
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055.001
attack.t1218.013
·
Share on:
twitter
facebook
linkedin
copy
Modify Group Policy Settings
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1484.001
·
Share on:
twitter
facebook
linkedin
copy
Modify Group Policy Settings - ScriptBlockLogging
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1484.001
·
Share on:
twitter
facebook
linkedin
copy
Modify User Shell Folders Startup Value
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1547.001
·
Share on:
twitter
facebook
linkedin
copy
Moriya Rootkit - System
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Moriya Rootkit File Created
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
New Country
calendar
Aug 12, 2024
·
attack.t1078
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
New Service Creation Using PowerShell
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Nimbuspwn Exploitation
calendar
Aug 12, 2024
·
attack.privilege-escalation
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
OMIGOD HTTP No Authentication RCE
calendar
Aug 12, 2024
·
attack.privilege-escalation
attack.initial-access
attack.execution
attack.lateral-movement
attack.t1068
attack.t1190
attack.t1203
attack.t1021.006
attack.t1210
·
Share on:
twitter
facebook
linkedin
copy
OMIGOD SCX RunAsProvider ExecuteScript
calendar
Aug 12, 2024
·
attack.privilege-escalation
attack.initial-access
attack.execution
attack.t1068
attack.t1190
attack.t1203
·
Share on:
twitter
facebook
linkedin
copy
OMIGOD SCX RunAsProvider ExecuteShellCommand
calendar
Aug 12, 2024
·
attack.privilege-escalation
attack.initial-access
attack.execution
attack.t1068
attack.t1190
attack.t1203
·
Share on:
twitter
facebook
linkedin
copy
Password Provided In Command Line Of Net.EXE
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.lateral-movement
attack.t1021.002
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Path To Screensaver Binary Modified
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1546.002
·
Share on:
twitter
facebook
linkedin
copy
Possible Coin Miner CPU Priority Param
calendar
Aug 12, 2024
·
attack.privilege-escalation
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Potential Access Token Abuse
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1134.001
stp.4u
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2023-21554 QueueJumper Exploitation
calendar
Aug 12, 2024
·
attack.privilege-escalation
attack.execution
cve.2023-21554
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Dridex Activity
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055
attack.discovery
attack.t1135
attack.t1033
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via GlobalFlags
calendar
Aug 12, 2024
·
attack.privilege-escalation
attack.persistence
attack.defense-evasion
attack.t1546.012
car.2013-01-002
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Netsh Helper DLL
calendar
Aug 12, 2024
·
attack.privilege-escalation
attack.persistence
attack.t1546.007
attack.s0108
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via PowerShell User Profile Using Add-Content
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1546.013
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Via Security Descriptors - ScriptBlock
calendar
Aug 12, 2024
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Potential Privilege Escalation Attempt Via .Exe.Local Technique
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Potential Privilege Escalation Using Symlink Between Osk and Cmd
calendar
Aug 12, 2024
·
attack.privilege-escalation
attack.persistence
attack.t1546.008
·
Share on:
twitter
facebook
linkedin
copy
Potential Shim Database Persistence via Sdbinst.EXE
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1546.011
·
Share on:
twitter
facebook
linkedin
copy
Potential SystemNightmare Exploitation Attempt
calendar
Aug 12, 2024
·
attack.privilege-escalation
attack.t1068
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Event Viewer Child Process
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
car.2019-04-001
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Profile Modification
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1546.013
·
Share on:
twitter
facebook
linkedin
copy
PowerShell ShellCode
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Process Explorer Driver Creation By Non-Sysinternals Binary
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
Process Monitor Driver Creation By Non-Sysinternals Binary
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1068
·
Share on:
twitter
facebook
linkedin
copy
PSEXEC Remote Execution File Artefact
calendar
Aug 12, 2024
·
attack.lateral-movement
attack.privilege-escalation
attack.execution
attack.persistence
attack.t1136.002
attack.t1543.003
attack.t1570
attack.s0029
·
Share on:
twitter
facebook
linkedin
copy
PUA - AdvancedRun Execution
calendar
Aug 12, 2024
·
attack.execution
attack.defense-evasion
attack.privilege-escalation
attack.t1564.003
attack.t1134.002
attack.t1059.003
·
Share on:
twitter
facebook
linkedin
copy
PUA - AdvancedRun Suspicious Execution
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1134.002
·
Share on:
twitter
facebook
linkedin
copy
PUA - Wsudo Suspicious Execution
calendar
Aug 12, 2024
·
attack.execution
attack.privilege-escalation
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Renamed Mavinject.EXE Execution
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055.001
attack.t1218.013
·
Share on:
twitter
facebook
linkedin
copy
Rundll32 Registered COM Objects
calendar
Aug 12, 2024
·
attack.privilege-escalation
attack.persistence
attack.t1546.015
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Cron Task/Job - Linux
calendar
Aug 12, 2024
·
attack.execution
attack.persistence
attack.privilege-escalation
attack.t1053.003
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Cron Task/Job - MacOs
calendar
Aug 12, 2024
·
attack.execution
attack.persistence
attack.privilege-escalation
attack.t1053.003
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Task Creation Via Schtasks.EXE
calendar
Aug 12, 2024
·
attack.execution
attack.persistence
attack.privilege-escalation
attack.t1053.005
attack.s0111
car.2013-08-001
stp.1u
·
Share on:
twitter
facebook
linkedin
copy
Security Privileges Enumeration Via Whoami.EXE
calendar
Aug 12, 2024
·
attack.privilege-escalation
attack.discovery
attack.t1033
·
Share on:
twitter
facebook
linkedin
copy
Service DACL Abuse To Hide Services Via Sc.EXE
calendar
Aug 12, 2024
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Service Installation in Suspicious Folder
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
car.2013-09-005
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Service Installation with Suspicious Folder Pattern
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
car.2013-09-005
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Service Registry Key Read Access Request
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.persistence
attack.privilege-escalation
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Service Security Descriptor Tampering Via Sc.EXE
calendar
Aug 12, 2024
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Shell Process Spawned by Java.EXE
calendar
Aug 12, 2024
·
attack.initial-access
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
SOURGUM Actor Behaviours
calendar
Aug 12, 2024
·
attack.t1546
attack.t1546.015
attack.persistence
attack.privilege-escalation
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Standard User In High Privileged Group
calendar
Aug 12, 2024
·
attack.credential-access
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Startup Item File Created - MacOS
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1037.005
·
Share on:
twitter
facebook
linkedin
copy
Sticky Key Like Backdoor Execution
calendar
Aug 12, 2024
·
attack.privilege-escalation
attack.persistence
attack.t1546.008
car.2014-11-003
car.2014-11-008
·
Share on:
twitter
facebook
linkedin
copy
Sticky Key Like Backdoor Usage - Registry
calendar
Aug 12, 2024
·
attack.privilege-escalation
attack.persistence
attack.t1546.008
car.2014-11-003
car.2014-11-008
·
Share on:
twitter
facebook
linkedin
copy
Suspect Svchost Activity
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Browser Activity
calendar
Aug 12, 2024
·
attack.t1078
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Child Process Of SQL Server
calendar
Aug 12, 2024
·
attack.t1505.003
attack.t1190
attack.initial-access
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Child Process Of Veeam Dabatase
calendar
Aug 12, 2024
·
attack.initial-access
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Debugger Registration Cmdline
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1546.008
·
Share on:
twitter
facebook
linkedin
copy
Suspicious GetTypeFromCLSID ShellExecute
calendar
Aug 12, 2024
·
attack.privilege-escalation
attack.persistence
attack.t1546.015
·
Share on:
twitter
facebook
linkedin
copy
Suspicious New Service Creation
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious NTLM Authentication on the Printer Spooler Service
calendar
Aug 12, 2024
·
attack.privilege-escalation
attack.credential-access
attack.t1212
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Processes Spawned by WinRM
calendar
Aug 12, 2024
·
attack.t1190
attack.initial-access
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Suspicious RunAs-Like Flag Combination
calendar
Aug 12, 2024
·
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Scheduled Task Creation
calendar
Aug 12, 2024
·
attack.execution
attack.privilege-escalation
attack.persistence
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Scheduled Task Update
calendar
Aug 12, 2024
·
attack.execution
attack.privilege-escalation
attack.persistence
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Service DACL Modification Via Set-Service Cmdlet - PS
calendar
Aug 12, 2024
·
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Service Installation
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
car.2013-09-005
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Service Path Modification
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Shells Spawn by Java Utility Keytool
calendar
Aug 12, 2024
·
attack.initial-access
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Triple Cross eBPF Rootkit Execve Hijack
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Abusing Winsat Path Parsing - File
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Abusing Winsat Path Parsing - Registry
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using .NET Code Profiler on MMC
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using Consent and Comctl32 - File
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using Event Viewer RecentViews
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using EventVwr
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using IDiagnostic Profile - File
calendar
Aug 12, 2024
·
attack.execution
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using IEInstal - File
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using Iscsicpl - ImageLoad
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using MSConfig Token Modification - File
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using NTFS Reparse Point - File
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using Windows Media Player - File
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using Windows Media Player - Registry
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using WOW64 Logger DLL Hijack
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass via Event Viewer
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
car.2019-04-001
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass via ICMLuaUtil
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass via Sdclt
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
car.2019-04-001
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Via Wsreset
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
UAC Disabled
calendar
Aug 12, 2024
·
attack.privilege-escalation
attack.defense-evasion
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Extension Shim Database Installation Via Sdbinst.EXE
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1546.011
·
Share on:
twitter
facebook
linkedin
copy
Uncommon One Time Only Scheduled Task At 00:00
calendar
Aug 12, 2024
·
attack.execution
attack.persistence
attack.privilege-escalation
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Service Installation Image Path
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
car.2013-09-005
attack.t1543.003
·
Share on:
twitter
facebook
linkedin
copy
Unfamiliar Sign-In Properties
calendar
Aug 12, 2024
·
attack.t1078
attack.persistence
attack.defense-evasion
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
User Added To Root/Sudoers Group Using Usermod
calendar
Aug 12, 2024
·
attack.privilege-escalation
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
VsCode Powershell Profile Modification
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1546.013
·
Share on:
twitter
facebook
linkedin
copy
Windows Kernel Debugger Execution
calendar
Aug 12, 2024
·
attack.defense-evasion
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
WMI ActiveScriptEventConsumers Activity Via Scrcons.EXE DLL Load
calendar
Aug 12, 2024
·
attack.lateral-movement
attack.privilege-escalation
attack.persistence
attack.t1546.003
·
Share on:
twitter
facebook
linkedin
copy
WMI Persistence
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1546.003
·
Share on:
twitter
facebook
linkedin
copy
WMI Persistence - Script Event Consumer
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1546.003
·
Share on:
twitter
facebook
linkedin
copy
WMI Persistence - Security
calendar
Aug 12, 2024
·
attack.persistence
attack.privilege-escalation
attack.t1546.003
·
Share on:
twitter
facebook
linkedin
copy
to-top